Community discussions

MikroTik App

Search found 24 matches

by jlxl
Thu Jul 30, 2009 7:35 pm
Forum: General
Topic: VPN's Behind MT Dropping
Replies: 3
Views: 1263

Re: VPN's Behind MT Dropping

These clients are able to work when they first get the connection going, it almost seems like the connection is dropped from possible inactivity? I have in my firewall rules allowed all incoming traffic from their remote office to our network, and traffic is passing through... but what the heck woul...
by jlxl
Thu Jul 30, 2009 5:31 pm
Forum: General
Topic: VPN's Behind MT Dropping
Replies: 3
Views: 1263

Re: VPN's Behind MT Dropping

Service port for pptp is enabled. SHould I specify a port for it? or just leave it alone. IPSec nodes should have NAT-T support enabled to get through IPSec traffc over NAT. I had seen somewhere that mt does not support nat-t. Is there a way for me to add a different nat rule for these specific clie...
by jlxl
Thu Jul 30, 2009 4:04 pm
Forum: General
Topic: VPN's Behind MT Dropping
Replies: 3
Views: 1263

VPN's Behind MT Dropping

I had searched quite a few posts before posting here and did not really find a good answer as to what I can fix to correct this issue. All Mikrotik Routers are RB532A models running OS 3.24 with ospf routing enabled between remote subnets. 2 Mikrotiks are connected to public ip addresses on ether1 p...
by jlxl
Tue Jan 13, 2009 4:59 pm
Forum: General
Topic: NMAP scan results
Replies: 8
Views: 11714

Re: NMAP scan results

Thanks normis,
but I can actually telnet into those ports, even from addresses on my BlockList. No services are running on these ports that I have, but it still seems quite strange.
by jlxl
Tue Jan 13, 2009 3:44 pm
Forum: General
Topic: NMAP scan results
Replies: 8
Views: 11714

Re: NMAP scan results

I am doing an nmap intense scan and it still returns those 4 ports listed in my first post as being filtered open. I can still telnet into each port also. Discovered open port 25/tcp on xx.xx.xx.xx Discovered open|filtered port 25/tcp on xx.xx.xx.xx (xx.xx.xx.xx) is actually open Discovered open por...
by jlxl
Tue Jan 13, 2009 2:47 pm
Forum: General
Topic: NMAP scan results
Replies: 8
Views: 11714

Re: NMAP scan results

I wouldn't think so, these are my only NAT rules [admin@mt-router] > ip firewall nat pr Flags: X - disabled, I - invalid, D - dynamic 0 ;;; NAT chain=srcnat action=masquerade src-address=10.10.10.0/24 out-interface=ether1 1 ;;; VPN chain=dstnat action=netmap to-addresses=10.10.10.10 to-ports=60000 p...
by jlxl
Mon Jan 12, 2009 8:51 pm
Forum: General
Topic: NMAP scan results
Replies: 8
Views: 11714

NMAP scan results

I am doing testing against one of my routers using nmap. My firewall config adds ports scanners to a drop list and does appear to be dropping packets quickly after the scan is initiated but nmap continues to return these results: xx.xx.xx.xx is a public ip address Discovered open port 25/tcp on xx.x...
by jlxl
Thu Jul 17, 2008 5:12 am
Forum: General
Topic: Subnet Routing Config Trouble
Replies: 7
Views: 3760

Re: Subnet Routing Config Trouble

On R1, changed the outgoing interface to be ether1 for the masquerade nat rule. Logged into R2 and tried to ping 64.233.167.104 (google) and still got a no route to host. From R2 I can ping 192.168.1.1 From a pc behind R2 on the 10.10.10.0 LAN, I can ping 192.168.1.1 also, but nothing public (which ...
by jlxl
Thu Jul 17, 2008 3:28 am
Forum: General
Topic: Subnet Routing Config Trouble
Replies: 7
Views: 3760

Re: Subnet Routing Config Trouble

This is the Firewall for router R1: [admin@CLYCLPTEST] > ip firewall filter pr Flags: X - disabled, I - invalid, D - dynamic 0 ;;; Drop Public Broadcast Traffic chain=input action=drop dst-address-type=broadcast,multicast in-interface=ether1 1 X ;;; Disable Open Proxy chain=input action=drop src-add...
by jlxl
Wed Jul 16, 2008 11:20 pm
Forum: General
Topic: Subnet Routing Config Trouble
Replies: 7
Views: 3760

Subnet Routing Config Trouble

I feel dumb for asking this since it would seem simple enough. I have a small LAN that I was brought into that is an existing /24 network with ip addresses used up all over this space that I cannot change at this time to make subnetting easier. We are joining a new small dept to this LAN as a subnet...
by jlxl
Sat Jul 12, 2008 6:22 am
Forum: General
Topic: VLAN (Router to Switch)
Replies: 2
Views: 2669

Re: VLAN (Router to Switch)

Thanks for the reply. That does make sense and the thought crossed my brain that I may have needed to do more. I will give that a try, if adding two vlan's and using those works, I will do just that.

I will post back soon after this is tested.

Thanks again for your time.
by jlxl
Fri Jul 11, 2008 2:13 pm
Forum: General
Topic: VLAN (Router to Switch)
Replies: 2
Views: 2669

VLAN (Router to Switch)

I am setting up a vlan using a mikrotik RB500 router running v3.10 and a netgear FS726T managed switch. The switch supports vlans (802.1Q and Port Based) The router is setup using nat with ether1 connected to the wan and ether2 connected to the lan. The vlan is setup on the ether2 interface like thi...
by jlxl
Thu Apr 17, 2008 1:19 am
Forum: General
Topic: OpenVPN UDP - MT Server - Windows Client
Replies: 7
Views: 3183

Re: OpenVPN UDP - MT Server - Windows Client

Seems that way. Can this be confirmed by anyone at MT? I am looking intently at each version update's changelog to see if there has been any progress made with OpenVPN support or bug fixes, but so far I haven't seen anything.
by jlxl
Wed Apr 16, 2008 6:06 pm
Forum: General
Topic: OpenVPN UDP - MT Server - Windows Client
Replies: 7
Views: 3183

Re: OpenVPN UDP - MT Server - Windows Client

Bump.
by jlxl
Mon Apr 14, 2008 9:12 pm
Forum: General
Topic: OpenVPN UDP - MT Server - Windows Client
Replies: 7
Views: 3183

OpenVPN UDP - MT Server - Windows Client

I have not been able to use OpenVPN with MT as a server and the OpenVPN GUI running on WIndows using TCP reliably. I am able to keep it running with no issues when transferring small amounts of data of the vpn connection, but tranferring files from my remote station to my server causes OpenVPN to ti...
by jlxl
Wed Jan 23, 2008 10:08 pm
Forum: The User Manager
Topic: Pay Pal works but account doesn't activate
Replies: 2
Views: 2168

Re: Pay Pal works but account doesn't activate

First time setting up a hotpsot for use with paypal, have been at it for a few days now and I have been encountering this exact problem also. Account is created with no credits, username/password verified, paypal transaction works too. As the user tries to logon, "Invalid username or password&q...
by jlxl
Tue Sep 11, 2007 12:11 am
Forum: The Dude
Topic: WakeOnLAN
Replies: 1
Views: 1759

Re: WakeOnLAN

Attached is a small console app written in C# that I wrote to this: just pass is the pc MAC Address you want to wake and it handles the rest. This requires the .Net framework 2.0 to be installed also.
by jlxl
Thu Aug 02, 2007 8:45 pm
Forum: Wireless Networking
Topic: RouterOS v2.9.45 is out!
Replies: 34
Views: 6797

Re: RouterOS v2.9.45 is out!

Can you provide a bit of a description as to what the "Hardware Retries" feature does? I have a few devices that hopefully will benefit from this fix, and I would just like to understand a bit more about what is actually happening with it.

Thanks,
by jlxl
Tue Jul 24, 2007 5:16 pm
Forum: General
Topic: Strange Winbox Logins
Replies: 6
Views: 3319

Re: Strange Winbox Logins

A bit more info: The blacked out ip in the picture from my 1st post is the router where our Dude server sits behind. When I login to a device through the Dude, it comes from the same ip. My biggest issue is why there are so many logins. Would the Dude be trying to perform some action that would caus...
by jlxl
Tue Jul 24, 2007 4:12 pm
Forum: General
Topic: Strange Winbox Logins
Replies: 6
Views: 3319

Re: Strange Winbox Logins

Under /ip services we had changed all the service ports and we access our routers through our custom ports. 43 of our routers have public ip addresses on them, and until we changed the service ports we saw lots ssh login attacks etc... same as most people's complaints. We use firewall rules similiar...
by jlxl
Tue Jul 24, 2007 2:29 pm
Forum: General
Topic: Strange Winbox Logins
Replies: 6
Views: 3319

Strange Winbox Logins

Recently we have been seeing multiple login attempts through Winbox in our log: Most of these attempts are successful but last just a second before logging out. (See attached Image) Is this something with the Dude? It is not happening on all devices, just a random few it seems. It looks like every 2...
by jlxl
Tue Jul 10, 2007 6:50 am
Forum: General
Topic: Customer Public IP
Replies: 7
Views: 2545

Customer Public IP

Our current setup has an ap directly connected to fiber on Ether1. We are also using broadband-over-powerline devices as customer devices, and a bridged wireless setup currently while we are still deploying fiber throughout out network. Ether1 has a Public IP: XX.XXX.XX.XXX The bridge and all custom...
by jlxl
Tue Jul 03, 2007 2:08 pm
Forum: Scripting
Topic: Terminal.exe Command Line
Replies: 0
Views: 1722

Terminal.exe Command Line

Not really a scripting question: We have other devices that we use besides Mikrotik (Corinex AV200's) that require the use a Telnet to login to them. We use putty to login to them but we have to load a saved session every time and change the ip since these devices require that the "Implicit CR ...
by jlxl
Thu Jun 07, 2007 11:11 pm
Forum: General
Topic: Evaluate Firewall Rule
Replies: 1
Views: 1347

Evaluate Firewall Rule

I was trying to drop most of my inbound traffic except for remote admin connections and came across a method that worked, but I wondered if it was inefficient or prone to flaws: Mangle: ;;;SSH From Admin MAC Address chain=prerouting protocol=tcp dst-port=22 src-mac-address=xx:xx:xx:xx:xx:xx action=m...